mirror of
https://pagure.io/fedora-infra/ansible.git
synced 2026-05-02 06:20:26 +08:00
Add staging robosig config
Signed-off-by: Patrick Uiterwijk <puiterwijk@redhat.com>
This commit is contained in:
61
roles/robosignatory/files/robosignatory.staging.py
Normal file
61
roles/robosignatory/files/robosignatory.staging.py
Normal file
@@ -0,0 +1,61 @@
|
||||
config = {
|
||||
'logging': {
|
||||
'loggers': {
|
||||
'robosignatory': {
|
||||
'handlers': ['console', 'mailer'],
|
||||
'level': 'DEBUG',
|
||||
'propagate': False
|
||||
},
|
||||
},
|
||||
},
|
||||
|
||||
'robosignatory.enabled.tagsigner': True,
|
||||
'robosignatory.enabled.atomicsigner': True,
|
||||
|
||||
# Any tag prefixed with "module-" will be considered a module.
|
||||
'robosignatory.module_prefixes': ['module-'],
|
||||
|
||||
|
||||
'robosignatory.signing': {
|
||||
'backend': 'sigul',
|
||||
'user': 'autopen',
|
||||
'passphrase_file': '/etc/sigul/autosign.pass',
|
||||
'config_file': '/etc/sigul/client.conf'
|
||||
},
|
||||
|
||||
# The keys here need to be the same in the sigul bridge
|
||||
'robosignatory.koji_instances': {
|
||||
'primary': {
|
||||
'url': 'https://koji.stg.fedoraproject.org/kojihub',
|
||||
'options': {
|
||||
# Only ssl is supported at the moment
|
||||
'authmethod': 'kerberos',
|
||||
'principal': 'autosign/autosign01.stg.phx2.fedoraproject.org@STG.FEDORAPROJECT.ORG',
|
||||
'keytab': '/etc/krb5.autosign_autosign01.stg.phx2.fedoraproject.org.keytab',
|
||||
'krb_rdns': False
|
||||
},
|
||||
'mbs_user': 'mbs/mbs.stg.fedoraproject.org',
|
||||
'tags': [
|
||||
# Temporary tags
|
||||
# Infra tags
|
||||
# Gated coreos-pool tag
|
||||
# Gated rawhide and branched
|
||||
{
|
||||
"from": "f31-pending",
|
||||
"to": "f31",
|
||||
"key": "fedora-31",
|
||||
"keyid": "3c3359c4"
|
||||
},
|
||||
# Gated bodhi updates
|
||||
# Non-gated bodhi triggered
|
||||
],
|
||||
},
|
||||
},
|
||||
|
||||
'robosignatory.ostree_refs': {
|
||||
'fedora/rawhide/x86_64/iot': {
|
||||
'directory': '/mnt/fedora_koji/koji/compose/iot/repo/',
|
||||
'key': 'fedora-31'
|
||||
},
|
||||
}
|
||||
}
|
||||
@@ -1,6 +1,6 @@
|
||||
[client]
|
||||
bridge-hostname: sign-bridge1
|
||||
server-hostname: sign-vault1
|
||||
bridge-hostname: sign-bridge01.stg.phx2.fedoraproject.org
|
||||
server-hostname: sign-vault01.stg.phx2.fedoraproject.org
|
||||
client-cert-nickname: sigul-client-cert
|
||||
user-name: autopen
|
||||
|
||||
|
||||
Reference in New Issue
Block a user